5 ms·
If you are paranoid^, you wouldn't use TrueCrypt. http://brianpuccio.net/excerpts/is_truecrypt_really_safe_to_use http://brianpuccio.net/excerpts/is_truecrypt_r
by pig 15y ago
If you are paranoid^, you wouldn't use TrueCrypt.
http://brianpuccio.net/excerpts/is_truecrypt_really_safe_to_use http://brianpuccio.net/excerpts/is_truecrypt_really_safe_to_...
^ good sense of the word
- epochwolf 15y agoYikes! I am going to go bury my head in some nice sandy hole for a while and pretend the world is a nicer place than it really is. :(
- pig 15y agoSee this http://news.ycombinator.com/item?id=1533674 http://news.ycombinator.com/item?id=1533674
- TillE 15y agoIf you toss out the GUI stuff and the boilerplate encryption algorithms, the amount of important code in TrueCrypt is fairly small. It has, naturally enough, been subjected to attempts to break it: http://www.zdnet.co.uk/news/security-management/2008/07/17/schneier-research-team-cracks-truecrypt-39448526/ http://www.zdnet.co.uk/news/security-management/2008/07/17/s... Writing a sentence like "Some folks claim it has a backdoor" is painfully dishonest, manipulative, and scummy.
- mynegation 15y ago> If you toss out the GUI stuff and the boilerplate encryption algorithms, the amount of important code in TrueCrypt is fairly small. First of all, even if you use "boilerplate" encryption algorithms, crypto is ridiculously easy to get wrong, especially in a very demanding setting of disk encryption. Second, TrueCrypt's ability to present its volumes as virtual drives/mountable images is no small feat (both in Linux and NT).
- AdamGibbins 15y agoI can't speak for early 2009 when that article was published, but does any of this stand true today still? They have a changelog here: http://www.truecrypt.org/docs/?s=version-history http://www.truecrypt.org/docs/?s=version-history Their contact page says they're registered in the US and gives an address: http://www.truecrypt.org/contact http://www.truecrypt.org/contact OK, can't speak for their forum banning as I'm not familiar with that situation and correct I cannot find any public repositories - but that's not too rare for some open source projects. The reasons for being partially anonymous are pretty clear, I doubt various governments are a great fan of TrueCrypt especially with its plausible deniability.
- pig 15y agoDid you wonder why they have their address in that page as an image? Apparently it is also near an air force base http://news.ycombinator.com/item?id=1533674 http://news.ycombinator.com/item?id=1533674
- bmnbug 15y agoI made a question on Quora [1] for this in case anyone wants to contribute. I've seen alot of conflicting discussion on Hacker News as to the authenticity of TrueCrypt. Hopefully we can continue the dialogue and organize the response over there, as it may go beyond the scope of the discussion here, where it arguably only has a tenuous connection to amazon cloud storage or other web storage services. [1] http://www.quora.com/Is-TrueCrypt-safe http://www.quora.com/Is-TrueCrypt-safe
- mryan 15y agoWhile I agree that we should not blindly place trust in security tools and assume we are safe, this link [1] gives me some optimism about TC's security (if it is to be believed... that's the problem with paranoia). [1] http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/ http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto...